Privacy Policy

Effective date: February 7, 2026

Overview

OptionTurtle (“we”, “us”, “our”) provides intraday trading tools, risk management and copy-trading services. This Privacy Policy explains how we collect, use, disclose and protect personal information when you use OptionTurtle’s websites and services, including signing in with Google.

Information we collect

  • Identity & account information — When you sign in with Google we receive basic profile information such as your name, email address and profile picture (via the openid, email, and profile scopes). We use Google’s OAuth to authenticate you; we only store the minimum data required to create and manage your account.
  • Session and device data — We store session identifiers, IP address, browser/agent, and basic telemetry needed to operate the service, detect abuse and troubleshoot issues.
  • Application data — Any data you provide via the app (trade preferences, copy-trade settings, trade history saved in your account) is stored as part of your account.
  • Third-party tokens — We exchange authorization codes for tokens during OAuth flows (these are stored briefly as needed). We never publish client secrets or tokens publicly.

How we use information

We use your information to:

  • Authenticate and create or manage your account;
  • Provide, operate and improve the OptionTurtle service;
  • Perform analytics and error tracking to maintain service reliability;
  • Communicate about your account, security, and important service notices;
  • Comply with legal obligations and prevent abuse or fraud.

Cookies & similar technologies

We use cookies and server-side sessions to maintain your log-in state and preferences. For OAuth security we use a short-lived oauth_state token (stored server-side in a secure store and a cookie for defense-in-depth). Session cookies are set with HttpOnly, Secure and SameSite=None for cross-site OAuth flows. You can control cookies through your browser settings, but disabling cookies may prevent sign-in or other features from working.

Third-party services

We use third-party providers to operate and secure the service, including but not limited to:

  • Google — for Sign-In and OAuth token verification;
  • AWS — hosting and infrastructure;
  • Redis — short-lived server-side state store;
  • Cashfree — payment provider (where applicable).

Data retention & deletion

We retain personal data as needed to provide the service, comply with legal obligations, resolve disputes and enforce our agreements. If you wish to delete your account and personal data, contact support@optionturtle.com and we will process the deletion request in accordance with applicable law. Note: some transactional or legal records may be retained for compliance purposes.

Security

We implement reasonable administrative, technical and physical safeguards to protect your personal information. This includes using HTTPS, secure cookies, and limiting access to production systems. However, no system can be completely secure — if you observe suspicious activity on your account, contact us immediately.

Children

OptionTurtle is not directed to children under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children.

International transfers

Your data may be stored or processed in countries other than your own. We take reasonable steps to ensure appropriate protections are in place when transferring personal data internationally.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, port, or delete your personal data. To exercise these rights, contact support@optionturtle.com. We will respond in accordance with applicable law.

Changes to this policy

We may update this Privacy Policy from time to time. The “Effective date” at the top will indicate when the policy was last updated.

Contact

For questions about this Privacy Policy or your personal data:
Email: support@optionturtle.com
Technical contact: abhi.sin05@gmail.com